Brinks Home Hit via Microsoft Entra Vishing

eSecurity Planet · Medium sophistication
Last updated August 1, 2026

Brinks Home says it is investigating a cybersecurity incident after the ShinyHunters group claimed it broke in by calling employees and tricking them into approving Microsoft Entra authentication actions. The attacker is threatening to publish data it claims to have stolen, including alleged Salesforce customer records and employee information.

How the Attack Reportedly Worked

Brinks Home has said it is investigating a cybersecurity incident after the group ShinyHunters claimed responsibility, stating the intrusion began with a Microsoft Entra vishing campaign. Rather than exploiting a software flaw, the described method relied on phone calls to employees, persuading them to approve authentication requests, register attacker-controlled devices, or complete identity verification steps. If successful, these actions would grant attackers legitimate-looking access to corporate accounts, bypassing many technical controls entirely.

Brinks Home confirmed that the attacker threatened to publicly release data but has not confirmed what, if anything, was actually accessed. ShinyHunters has alleged theft of Salesforce customer records, employee PII, and large volumes of customer support chat logs, but these claims have not been independently verified.

Why This Type of Attack Succeeds

Vishing campaigns targeting identity systems succeed because they exploit the human element rather than a technical vulnerability. Employees are conditioned to be helpful and responsive to IT-sounding requests, especially when a caller frames the situation as urgent, such as stopping suspicious activity or restoring account access. When an employee approves an authentication prompt or allows a new device to be registered, the resulting access looks legitimate to monitoring systems, making detection harder after the fact.

What to Watch For

Defenders and employees should be alert to several warning signs:

  • An unsolicited phone call asking you to approve an authentication or MFA prompt you did not initiate
  • Pressure or urgency to act immediately on an identity-related request
  • Requests to enroll a new device or change authentication settings during a call
  • Callers claiming to be internal IT or Microsoft Entra support without a way to verify their identity

These tactics target all employees, but help desk staff, IAM teams, and customer support are especially attractive targets because of the access and trust associated with their roles.

Building Resistance

Organizations can reduce exposure to this style of attack by:

  • Treating unexpected calls about account security as suspicious and verifying requests through a known internal IT channel before approving any login prompt
  • Training employees to never approve authentication prompts they did not start, and to report them immediately
  • Strengthening help desk identity verification procedures and restricting who can enroll new devices or MFA methods
  • Monitoring Microsoft Entra, Salesforce, and other cloud platforms for unusual authentication activity

Because this technique targets identity rather than infrastructure, technical controls alone are not enough. Combining phishing-resistant MFA, tighter help desk verification, and ongoing monitoring gives organizations a better chance of catching these attempts before access is granted.

Key findings

  • Brinks Home is investigating an incident after attackers claimed they used a Microsoft Entra voice phishing (vishing) campaign against employee identities.
  • Brinks Home confirmed the attacker threatened to release data publicly, but did not confirm what data was accessed.
  • ShinyHunters alleges theft of Salesforce customer records, employee PII, and millions of customer support chat logs (claims not independently verified).
  • The described method focuses on manipulating employees to approve login/authentication activity rather than exploiting a software vulnerability.
  • The article recommends phishing-resistant MFA, stronger identity verification (especially help desk), and monitoring for unusual authentication activity in Entra and SaaS apps.

Who’s being targeted

  • Commonly targeted roles: All employees, IT helpdesk, Identity & access management (IAM) team, Customer support, Security operations (SOC), Finance/Legal leadership (extortion readiness).
  • Affected industries: Residential security services, Smart home / home automation, SaaS / cloud services (Salesforce identity ecosystems).
  • Attack channels: vishing.
  • Impersonated: Internal IT Helpdesk / Microsoft Entra support.

Red flags to watch for

  • Unsolicited phone call asking you to approve an authentication prompt
  • Pressure/urgency to act immediately on an authentication request you did not initiate
  • Requests to enroll/register a new device or change authentication settings during the call
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What happened in the Brinks Home incident?

Brinks Home said it is investigating a cybersecurity incident after ShinyHunters claimed to have breached the company using a Microsoft Entra vishing campaign targeting employees.

How did the attackers reportedly gain access?

According to the claims, attackers called employees and persuaded them to approve authentication requests, register attacker-controlled devices, or complete identity verification steps that granted access to corporate accounts.

What data was allegedly stolen?

ShinyHunters alleges theft of Salesforce customer records, employee PII, and customer support chat logs, though Brinks Home has not confirmed what data was accessed and these claims are not independently verified.

How can organizations defend against this type of attack?

Recommended defenses include strengthening help desk identity verification, restricting unauthorized device registration and MFA enrollment, and monitoring Microsoft Entra and Salesforce for unusual authentication activity.

Read the video transcript

Brinks Home just got hit because employees answered one bad question: “Can you approve that Microsoft Entra prompt for me?” The caller says, “Hi, this is IT support. We’re seeing an authentication issue in Microsoft Entra, can you approve the verification prompt so we can secure your access?” That’s the whole play. According to ShinyHunters, this Microsoft Entra vishing trick let them get into Salesforce, employee data, even millions of support chats, without hacking software, just convincing people to tap Approve. If you ever get a surprise call about your account, and they want you to approve a prompt, your move is simple: hang up, and call your real IT number or open the official ticketing tool to verify first.

Similar attacks

QR-Code PDFs Steal Microsoft 365 Logins

QR-Code PDFs Steal Microsoft 365 Logins

Cisco Talos incident responders reported phishing as the most common initial entry method in recent real-world incidents, including an ongoing QR-code phishing…

July 28, 2026